⤷ Title: Hacker’s Holiday 2026: Towel on the Sunbed Writeup
════════════════════════
𐀪 Author: Angeline Marietta Charley
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 12:53:37 GMT
════════════════════════
⌗ Tags: #web_security #race_condition #cybersecurity #hacking #tryhackme
════════════════════════
𐀪 Author: Angeline Marietta Charley
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 12:53:37 GMT
════════════════════════
⌗ Tags: #web_security #race_condition #cybersecurity #hacking #tryhackme
Medium
Exploiting a Race Condition (TOCTOU) in TryHackMe’s “Towel on the Sunbed”
Room: Towel on the Sunbed (TryHackMe Hacker’s Holiday 2026)
⤷ Title: The Request Changed. The Security Rule Didn’t.
════════════════════════
𐀪 Author: Akshit Kakani
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 11:55:32 GMT
════════════════════════
⌗ Tags: #web_security #ethical_hacking #penetration_testing #application_security #cybersecurity
════════════════════════
𐀪 Author: Akshit Kakani
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 11:55:32 GMT
════════════════════════
⌗ Tags: #web_security #ethical_hacking #penetration_testing #application_security #cybersecurity
Medium
The Request Changed. The Security Rule Didn’t.
Exploring HTTP Verb Tampering and Broken Access Control
⤷ Title: OWASP Top 10: A05:2025(CWE-89) SQL Injection
════════════════════════
𐀪 Author: Okan
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 09:33:18 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #cybersecurity #web_security #sql_injection #infosec
════════════════════════
𐀪 Author: Okan
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 09:33:18 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #cybersecurity #web_security #sql_injection #infosec
Medium
OWASP Top 10: A05:2025(CWE-89) SQL Injection
Introduction
⤷ Title: A Bank’s HR Team Was Hacking Themselves Every Time They Opened My Job Application
════════════════════════
𐀪 Author: tushar
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 12:24:18 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #web_security #cybersecurity #xs #bug_bounty
════════════════════════
𐀪 Author: tushar
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 12:24:18 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #web_security #cybersecurity #xs #bug_bounty
Medium
A Bank’s HR Team Was Hacking Themselves Every Time They Opened My Job Application
How a 4-character file name prefix turned a resume upload into a persistent backdoor into a Ukrainian bank’s HR panel — and why this class…
⤷ Title: DOM XSS using web messages
════════════════════════
𐀪 Author: Mubin mujawar
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 10:51:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #xss_vulnerability #portswigger #javascript #web_security
════════════════════════
𐀪 Author: Mubin mujawar
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 10:51:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #xss_vulnerability #portswigger #javascript #web_security
Medium
DOM XSS using web messages
Exploiting an Unchecked postMessage Listener — DOM XSS Using Web Messages (PortSwigger Academy)
⤷ Title: Running bWAPP on Latest XAMPP (PHP 8.x) - Fixing SQL Lab Compatibility Issues
════════════════════════
𐀪 Author: Om Barot
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 19:34:50 GMT
════════════════════════
⌗ Tags: #sql_injection #ethical_hacking #web_security #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Om Barot
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 19:34:50 GMT
════════════════════════
⌗ Tags: #sql_injection #ethical_hacking #web_security #penetration_testing #cybersecurity
Medium
Running bWAPP on Latest XAMPP (PHP 8.x) - Fixing SQL Lab Compatibility Issues
Introduction
⤷ Title: (BAC)Insecure direct object references
════════════════════════
𐀪 Author: Abdallh Mohamed
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 16:14:39 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #penetration_testing #web_security #broken_access_control #bug_bounty_writeup
════════════════════════
𐀪 Author: Abdallh Mohamed
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 16:14:39 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #penetration_testing #web_security #broken_access_control #bug_bounty_writeup
Medium
(BAC)Insecure direct object references
firstly we explain what of the Insecure direct object references???
⤷ Title: Reading a Website Like a Pentester: What to Test in Every Functionality
════════════════════════
𐀪 Author: Shruti Vijay Shinde
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 07:18:07 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #penetration_testing #web_security #cybersecurity
════════════════════════
𐀪 Author: Shruti Vijay Shinde
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 07:18:07 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #penetration_testing #web_security #cybersecurity
Medium
Reading a Website Like a Pentester: What to Test in Every Functionality
When a normal user opens a web application, they usually focus on what they can do with it search for a product, log in to an account…
⤷ Title: Hacker Holidays Day 2: The Room That Wasn’t on Any Floor Plan
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 14:07:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #ctf #web_security #infosec #tryhackme
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 14:07:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #ctf #web_security #infosec #tryhackme
Medium
Hacker Holidays Day 2: The Room That Wasn’t on Any Floor Plan
The setup
⤷ Title: Blind SQL Injection with Conditional Responses - PortSwigger Lab Write-Up
════════════════════════
𐀪 Author: Om Barot
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 14:10:57 GMT
════════════════════════
⌗ Tags: #ethical_hacking #web_security_academy #sql_injection #burpsuite #cybersecurity
════════════════════════
𐀪 Author: Om Barot
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 14:10:57 GMT
════════════════════════
⌗ Tags: #ethical_hacking #web_security_academy #sql_injection #burpsuite #cybersecurity
Medium
Blind SQL Injection with Conditional Responses - PortSwigger Lab Write-Up
Introduction